KorotchaimKorotchaim
KorotchaimKorotchaim

SentinelOne

SentinelOne logo
Cybersecurity · Endpoint protection · XDR · AI-driven security Mountain View (HQ) · Tel Aviv (R&D), Boston, Prague, Tokyo~2,500 globally · several hundred in Israel R&D

SentinelOne's Tel Aviv R&D is the engine behind the AI-native shift the company has been making since the August 2025 Prompt Security acquisition ($250M, Israeli LLM-runtime startup). Junior intake here splits between ML / threat-research roles (heavy in malware analysis + Linux/macOS internals) and platform engineering on the AI-driven SIEM that will absorb the September 2025 Observo AI acquisition. Greenhouse ATS, English-first.

ATS
Greenhouse
Hebrew
helpful
Citizenship
not required
Last verified
2026-05-02

Programs

ML Research Intern (Tel Aviv)

Project-based ML research role inside SentinelLabs / the broader Tel Aviv R&D. Active areas in 2026 include LLM-runtime security (post-Prompt acquisition), telemetry-pipeline ML (post-Observo AI announcement), and threat-detection model training on SentinelOne's endpoint dataset. Interns ship code into product, not just papers.

Eligibility
MSc / PhD students in CS / EE / data-science with hands-on ML model training. Threat-detection or anomaly-detection coursework or thesis work is a meaningful tiebreaker. Interns who can articulate a research direction tied to one of SentinelOne's product areas convert at higher rates than generalists.
Schedule
3–6 months · part-time during semester / full-time on summer · Tel Aviv office.
Apply on SentinelOne careers

Cyber Threat Research Intern (Tel Aviv)

Reverse-engineering and malware-analysis projects inside SentinelLabs. Heavier than the ML track on Linux internals, macOS internals, and binary analysis tooling (IDA, Ghidra, Frida). Most interns come from CS programs with a security minor, military signal-corps backgrounds, or active CTF participation.

Eligibility
BSc / MSc / PhD students with hands-on RE / malware-analysis. Even a single CTF write-up published online counts as evidence. Linux + macOS internals familiarity (read kernel docs, debugged a kernel module, etc.) is a strong screen.
Schedule
3–6 months · part-time during semester · Tel Aviv office.
Apply on SentinelOne careers

Who they hire

SentinelOne's Tel Aviv R&D is one of the more academically-oriented Israeli cyber operations. The ML-research track pulls heavily from MSc / PhD students at the Technion, Tel Aviv University, and the Hebrew University; the threat-research track pulls from CS-with-security students plus a meaningful share of 8200 / 9900 / Mamram alumni. SentinelLabs has a published research output (the Greenhouse board lives at boards.greenhouse.io/embed/job_board?for=sentinellabs — distinct from the corporate board, which signals how seriously the lab is treated internally). English is the working language for cross-region collaboration with Mountain View; Hebrew helps with team rituals but isn't a screening filter.

The process

Pipeline runs through Greenhouse — the SentinelLabs board is dedicated, separate from the corporate Greenhouse instance. After CV screen — typically 7–14 days at SentinelLabs' volume — successful candidates hit a domain-specific technical screen. ML candidates: 60-minute conversation about your most recent project + a take-home with a small dataset; the bar is methodology, not Kaggle ranking. Threat-research candidates: 60-minute walkthrough of one CTF you've solved or a malware sample you've reversed, plus follow-ups on Linux/macOS internals. Tech panel: 90 minutes with two senior researchers (live coding + research-direction discussion). Final round is research-group fit. Total time from CV to offer is 4–7 weeks. Code review during the take-home is famously strict — preference for candidates who write tests and document assumptions.

SentinelOne CV — what to include

Common mistakes that get you filtered

Insights that aren't on the company's careers page

Frequently asked questions about SentinelOne

How do I apply to SentinelOne?+

SentinelOne uses Greenhouse for application tracking. Pipeline runs through Greenhouse — the SentinelLabs board is dedicated, separate from the corporate Greenhouse instance. After CV screen — typically 7–14 days at SentinelLabs' volume — successful candidates hit a domain-specific technical screen. ML candidates: 60-minute conversation about your most recent project + a take-home with a small dataset; the bar is methodology, not Kaggle ranking. Threat-research candidates: 60-minute walkthrough of one CTF you've solved or a malware sample you've reversed, plus follow-ups on Linux/macOS internals. Tech panel: 90 minutes with two senior researchers (live coding + research-direction discussion). Final round is research-group fit. Total time from CV to offer is 4–7 weeks. Code review during the take-home is famously strict — preference for candidates who write tests and document assumptions.

What does SentinelOne look for in candidates?+

SentinelOne's Tel Aviv R&D is one of the more academically-oriented Israeli cyber operations. The ML-research track pulls heavily from MSc / PhD students at the Technion, Tel Aviv University, and the Hebrew University; the threat-research track pulls from CS-with-security students plus a meaningful share of 8200 / 9900 / Mamram alumni. SentinelLabs has a published research output (the Greenhouse board lives at boards.greenhouse.io/embed/job_board?for=sentinellabs — distinct from the corporate board, which signals how seriously the lab is treated internally). English is the working language for cross-region collaboration with Mountain View; Hebrew helps with team rituals but isn't a screening filter.

What's the interview process at SentinelOne?+

Pipeline runs through Greenhouse — the SentinelLabs board is dedicated, separate from the corporate Greenhouse instance. After CV screen — typically 7–14 days at SentinelLabs' volume — successful candidates hit a domain-specific technical screen. ML candidates: 60-minute conversation about your most recent project + a take-home with a small dataset; the bar is methodology, not Kaggle ranking. Threat-research candidates: 60-minute walkthrough of one CTF you've solved or a malware sample you've reversed, plus follow-ups on Linux/macOS internals. Tech panel: 90 minutes with two senior researchers (live coding + research-direction discussion). Final round is research-group fit. Total time from CV to offer is 4–7 weeks. Code review during the take-home is famously strict — preference for candidates who write tests and document assumptions.

Does SentinelOne hire juniors or interns?+

Yes. SentinelOne runs 2 dedicated student/junior programs — full details listed above.

Does your CV match SentinelOne?

Korotchaim scores your CV against an actual SentinelOne job description. Free preview — no signup.

Try the demo

Related guides

Sources

  1. https://www.sentinelone.com/careers/ · official · 2026-05-02
  2. https://boards.greenhouse.io/embed/job_board?for=sentinellabs · official · 2026-05-02
  3. https://en.wikipedia.org/wiki/SentinelOne · third-party · 2026-05-02
  4. https://www.calcalistech.com/ctechnews/article/im5ma59bu · news · 2026-05-02
  5. https://www.sentinelone.com/press/sentinelone-to-acquire-observo-ai-to-revolutionize-siem-and-security-operations/ · official · 2026-05-02